Requisition ID:  5108

Technical Manager, Identity & Access Management (PAM)

The Hong Kong Jockey Club

Founded in 1884, The Hong Kong Jockey Club (“the Club”) is a world-class racing club that acts continuously for the betterment of our society. The Club has a unique integrated business model, comprising racing and racecourse entertainment, a membership club, responsible sports wagering and lottery, and charities and community contribution. Through this model, the Club generates economic and social value for the community and supports the HKSAR Government in combatting illegal gambling.

Who are we?

We are the IT Division of HKJC, a vibrant community of over 1,500 dedicated professionals working collaboratively across Hong Kong and Shenzhen.

Our team is a diverse mix of individuals from various backgrounds, from all across the world. We embrace our humanity, recognizing that each of us brings unique strengths and perspectives. This diversity not only enriches our work environment but also drives our innovation and creativity as we strive to achieve our collective goals.

What do we do?

We design, build, and operate the technology that powers the Club. Our primary focus is on delivering the service that supports our hospitality, racing and wagering operations, to ensure that our customers and members enjoy exceptional experiences.

We also deliver the changes necessary to drive business growth through new products and services. And, we are committed to safeguarding the Club by protecting it from external threats, providing a secure and resilient technological environment.

The Department

The Cyber Security Department is essential to the Club’s ongoing success, safeguarding information assets, IT systems, networks, and cloud platforms while ensuring the resilience and continuity of critical operations. Through the implementation of strong risk governance frameworks and cybersecurity standards, the department protects the Club against emerging threats and ensures compliance with regulatory requirements in Hong Kong and China.

As the first line of defense, the department plays a key role in maintaining the Club’s reputation and operational resilience. Its core responsibilities include identifying and addressing vulnerabilities, protecting sensitive information, ensuring rapid incident response, overseeing access management, and promoting Club-wide cybersecurity awareness.

The Job

  • Lead the onboarding and integration of enterprise applications and platforms into the Club's IAM, IGA, and PAM solutions to deliver centralised authentication and access management capabilities, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), identity lifecycle management, access provisioning and de-provisioning, privileged access controls, and governance activities such as access reviews and re-certifications
  • Provide day-to-day operational support for IAM, IGA, and PAM services by assisting business users and operational teams in resolving identity and access-related issues, while coordinating with external vendors to ensure timely resolution, service stability, and adherence to support commitments
  • Design, implement, enhance, and automate IAM, IGA, and PAM workflows and processes in accordance with business requirements, the Club's information security policies and standards, and industry best practices to improve operational efficiency, user experience, and security posture
  • Assess, plan, test, and implement platform maintenance activities, including system and database upgrades, security patching, certificate renewals, security hardening, and vulnerability remediation, to ensure IAM, IGA, and PAM platforms remain secure, resilient, and supported
  • Act as the IAM Subject Matter Expert (SME) by providing technical leadership and consultation on authentication, authorisation, identity governance, and privileged access management requirements, defining solution designs that support business objectives while maintaining strong cybersecurity controls
  • Collaborate with project teams and stakeholders, including Project Managers, Architecture, Design and Delivery teams, Portfolio teams, and business users, to implement, integrate, and operationalise IAM, IGA, and PAM initiatives and services
  • Identify opportunities to strengthen identity security capabilities through process enhancements, automation, and remediation of control gaps, working closely with team members and Cyber Security management to continuously improve the effectiveness of IAM, IGA, and PAM services
  • Produce and maintain operational metrics, reporting, and Key Performance Indicators (KPIs) to support service monitoring, operational governance, and management reporting
  • Contribute to a collaborative, diverse, and inclusive culture built on trust and respect, while actively supporting cross-team, cross-division, and departmental initiatives that drive shared outcomes and organisational success

About You

  • University degree in Information Technology, Management Information Systems, Engineering, Computer Science, or a related discipline
  • Minimum 5 to 8 years of experience in technical IT roles, with at least 3 years of hands-on experience in enterprise Identity Security technologies, including Identity and Access Management (IAM), Identity Governance & Administration (IGA), and/or Privileged Access Management (PAM) solutions
  • Hands-on experience in the installation, configuration, integration, administration, and support of one or more Identity Security platforms, such as Microsoft Entra ID, Ping Identity/ForgeRock, SailPoint, Saviynt, CyberArk, Delinea, Okta, Oracle Identity Management, or equivalent technologies
  • Hands-on experience in integrating authentication and access management technologies, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), identity federation, biometrics, and passwordless authentication across on-premises and cloud environments
  • Experience in implementing and operating identity governance and administration processes, including access request and approval workflows, provisioning and de-provisioning, access certifications and re-certifications, Role-Based Access Control (RBAC), Segregation of Duties (SoD), role mining, and compliance policy enforcement
  • Experience with Privileged Access Management (PAM) concepts and technologies, including privileged account onboarding, credential vaulting, privileged session management, least-privilege principles, and privileged access governance
  • Hands-on experience in scripting and automation using PowerShell, BeanShell, or similar scripting languages
  • Strong understanding of authentication, authorisation, identity lifecycle management, identity governance, and privileged access management principles and best practices
  • Technical experience in implementing and supporting federation and identity protocols such as SAML, OAuth 2.0, OpenID Connect (OIDC), ADFS, and related identity integration standards
  • Strong understanding of Microsoft Active Directory, Microsoft Entra ID, Windows, Linux, macOS, mobile operating systems, networking fundamentals, directory services, and cybersecurity concepts
  • Relevant professional and vendor certifications in cybersecurity, IAM, IGA, or PAM technologies (e.g. CISSP, CISM, CIAM, Microsoft, ForgeRock/Ping, SailPoint, Saviynt, CyberArk, Delinea, Okta, or equivalent) will be an added advantage

Apply Now!

We offer competitive salary and benefits packages, a dynamic working environment and development opportunities.

 

Add horsepower to your career today. Click the “Apply Now” button to create an account and submit your application.

Equal Opportunity and Inclusive Hiring

We are an equal opportunity employer and strive to create an inclusive workplace for all. Applicants from diverse backgrounds are welcomed to apply. If you have any special needs or require accommodations during the interview process, please e-mail us via careers@hkjc.org.hk. Personal data provided by job applicants will be used strictly in accordance with the Club's notice to employees and job applicants relating to the Personal Data (Privacy) Ordinance. A copy of which will be provided immediately upon request.

Share Page
Share this Job :

To share this job on WeChat, please click the button below to copy the link: